All Products
Search
Document Center

Security Center:Release notes

Last Updated:Jun 29, 2026

Track feature releases, enhancements, and deprecations for Security Center.

August–December 2025

Feature

Change type

Description

Release date

Related documentation

Agentic SOC

Enhancement

Data import now supports Azure.

December 2025

Import Azure log data

Vulnerability management

New feature

Vulnerability management now supports automated vulnerability remediation.

December 2025

View and handle vulnerabilities

Agentic SOC

Enhancement

Automated response rules now include the following capabilities:

  • Trigger rules based on security event updates.

  • The Add Alert to Whitelist and update owner actions are now available.

December 2025

Automated response rule

Agentic SOC / Detection and Response

New feature

The update owner feature is available for security event handling.

December 2025

Assess and handle Agentic SOC security events, Assess and handle CWPP security events

Agentic SOC

New feature

Data import now supports ingesting data from Alibaba Cloud OSS.

November 2025

General data import process

Agentic SOC

Enhancement

Add enrichment information to custom alerting rules.

November 2025

Detection rules

Connect to Baidu Cloud assets

New feature

Manage Baidu Cloud assets in Security Center.

November 2025

Onboard Baidu Cloud assets by using an AccessKey

Agentless detection

Enhancement

Agentless detection now supports default scanning for new assets.

November 2025

Agentless detection, One-click onboarding policies and billing for pay-as-you-go services

Malicious file detection

New feature

Handle malicious file detection results.

November 2025

Handle detection results

One-click Policy Activation

Enhancement

One-click Policy Activation now includes Log Management, anti-ransomware, and vulnerability remediation.

November 2025

One-click onboarding policies and billing for pay-as-you-go services

Log Analysis and Log Management

Enhancement

Purchase and use Log Analysis and Log Management concurrently.

November 2025

Purchase Security Center, Migration guide from Log Analysis to Log Management

Overview

Deprecation

The previous overview page is deprecated.

November 2025

Assess and handle CWPP security events

Anti-ransomware

Enhancement

The anti-ransomware feature now supports the pay-as-you-go billing method.

October 2025

Anti-ransomware service overview, Purchase Security Center, Activate and purchase the anti-ransomware service

Agentless detection

New feature

Agentless detection now supports scanning of host assets on AWS.

October 2025

Agentless detection

Cloud Security Posture Management (CSPM)

Enhancement

Cloud Security Posture Management (CSPM) now supports onboarding of assets from Volcengine.

September 2025

Onboard Volcengine assets by using an AccessKey, Add cloud assets for configuration checks

Agentic SOC

Enhancement

Schedule updates to the global_white_list watchlist using trusted IP address sources from Alibaba Cloud products and services.

September 2025

Watchlist

Billing

Enhancement

The pay-as-you-go plan now includes a basic service fee. Additionally, the term "protection level" replaces "protection edition".

September 2025

Purchase Security Center, Billing, [Notice] Pay-as-you-go billing change

Agentic SOC

Enhancement

Configure entity mapping for alerts in custom alerting rules.

September 2025

Detection rules

Detection and Response / Agentic SOC

Enhancement

The security event handling feature is now available to CWPP users.

September 2025

Assess and handle Agentic SOC security events

Agentic SOC

New feature

Response orchestration now includes the TaskContext, Threatbook, and Fortinet components.

August 2025

TaskContext component, Threatbook component, Third-party components (OpenAPI)

Attack Analysis

Migration

The Attack Analysis feature has been moved to network defense alerts under Security Alerts.

August 2025

Manage alerts, [Notice] Changes to Attack Analysis and Event Investigation

Agentic SOC

Enhancement

Product integration now supports batch onboarding of Alibaba Cloud native products and auto-discovery of multi-account Logstore data sources.

August 2025

Multi-account management

Malicious file detection

Enhancement

OSS file detection now supports real-time incremental scanning in the China region.

August 2025

Malicious file detection

July 2025

Feature name

Change type

Description

Affected editions

Release date

Related documents

Log management

Enhancement

The log management feature now supports the pay-as-you-go billing method.

All editions

July 29, 2025

Log management

Container security

Enhancement

Bind ACK assets to the Ultimate Edition.

Ultimate Edition

July 29, 2025

Agentless detection

Enhancement

Agentless detection now supports scanning in the Indonesia (Jakarta) region.

Users on the pay-as-you-go plan for agentless detection

July 29, 2025

Agentless detection

Malicious file detection

Enhancement

The malicious file detection feature now supports scanning OSS files up to 1 GB in the Security Center console, an increase from 500 MB.

Requires the malicious file detection add-on

July 16, 2025

Malicious file detection

Response orchestration

New feature

New workflow components are now available.

All editions

July 9, 2025

About workflow components

Agentic SOC

Enhancement

Access the upgrade assessment for Agentic SOC 2.0.

All editions

July 9, 2025

Host and container security license binding

Enhancement

Only the Ultimate Edition protects Lingjun assets, so they must be bound to this edition.

Anti-Virus Edition, Enterprise Edition, Advanced Edition

July 3, 2025

Manage host and container security licenses

Onboard multi-cloud assets

New feature

Security Center now supports onboarding Google Cloud assets in all regions outside the Chinese mainland.

All editions

July 2, 2025

Onboard Google Cloud assets by using a service account key

June 2025

Feature name

Change type

Description

Affected versions

Release date

Related documents

Cloud product configuration risk check

New

Adds configuration risk checks for cloud-native AI products on Azure and AWS.

Requires the cloud security posture management add-on.

June 18, 2025

Cloud product configuration risk check

AI security posture management

Enhancement

Adds an Overview card to the AI Asset page.

All versions

June 13, 2025

AI security posture management

Malicious file detection

Enhancement

Malicious file detection now supports pay-as-you-go.

Requires the malicious file detection add-on.

June 9, 2025

Application protection

Enhancement

Application protection now supports pay-as-you-go.

Requires the application protection add-on.

June 9, 2025

Billing details

Serverless security

Enhancement

Serverless security now offers tiered cumulative billing.

Available to users with pay-as-you-go enabled for Serverless assets.

June 9, 2025

Billing details

May 2025

Feature

Change type

Description

Affected versions

Release date

Documentation

Agentless detection

Enhancement

Agentless detection now supports alert notifications.

Available to users who have enabled pay-as-you-go for agentless detection.

2025-05-28

Notification settings

Security report

Enhancement

  • The optimized security report page now includes a cover page.

  • The report now includes data from CSPM and SDK scan tasks. It also provides additional data for attack analysis and RASP, and consolidates data across networks, hosts, and applications.

  • High-risk data, such as weak passwords, is now included in the report.

Advanced Edition, Enterprise Edition, and Ultimate Edition

2025-05-16

Security report

Log analysis

Enhancement

Log analysis now supports the delivery and storage of alert logs from agentless detection.

All editions

2025-05-12

Log types and field descriptions

New overview

Enhancement

  • The optimized subscription display lets you quickly view the usage of your purchased features.

  • Asset risk information is consolidated into a unified view, so you no longer need to switch regions to assess risk.

  • The overview now presents data in three stages—risk management, security protection, and security response—to help you manage risks more effectively.

  • A new product updates card lets you quickly see recent product changes.

All editions

2025-05-08

Overview (new)

April 2025

Feature name

Change type

Description

Affected versions

Release date

Related documentation

Anti-ransomware

Updated

Database protection policies now support selecting specific instances.

Requires the Anti-ransomware value-added service.

2025-04-29

Manage protection policies and clients

Cloud Security Posture Management

Updated

Cloud product configuration risk now supports custom check items.

Requires a paid subscription for Cloud Security Posture Management.

2025-04-25

Custom check items

Multi-cloud asset connection

New

Security Center now supports connecting Volcano Engine assets.

All editions

2025-04-02

Connect third-party cloud assets

March 2025

Feature name

Change type

Description

Affected editions

Release date

Related documentation

Baseline risk check

Updated

The entry point for this feature has been moved to the Baseline Risk tab on the Risk Governance > CSPM page in the Security Center console.

Advanced, Enterprise, and Ultimate

2025-03-31

Baseline risk check

Asset fingerprinting

New

Asset fingerprinting now supports collecting information about AI components.

Enterprise, Ultimate

2025-03-31

Asset fingerprinting

Asset exposure analysis

New

Asset exposure analysis can now identify exposed AI services deployed on servers.

Enterprise, Ultimate

2025-03-31

Asset exposure analysis

Vulnerability management

New

The application vulnerability feature can now detect vulnerabilities in AI applications.

Enterprise, Ultimate

2025-03-31

View and manage vulnerabilities

Image security scan

New

The image security scan can now flag images deployed through Platform for AI-Elastic Algorithm Service (PAI-EAS). It also detects sensitive information, such as API keys for Alibaba Cloud Model Studio, stored in plaintext during AI API calls.

Requires the image security scan add-on.

2025-03-31

View image risks and remediation instructions

Agentless detection

New

Agentless detection can now detect sensitive information, such as tokens for PAI-EAS, stored in plaintext during AI API calls.

Available to users who enable pay-as-you-go for agentless detection.

2025-03-31

Agentless detection

Cloud Security Posture Management

Updated

The cloud product configuration risk check feature now checks for AI Security Posture Management (AI-SPM).

Available to users who purchase or enable Cloud Security Posture Management.

2025-03-31

Cloud product configuration risk check

The cloud product configuration risk check feature now checks for Kubernetes Security Posture Management (KSPM).

Available to users who purchase or enable Cloud Security Posture Management.

2025-03-28

Log management

Deprecated

Security Center no longer supports the delivery and storage of network logs through Log Analysis or the log management feature of Agentic SOC.

Affects users who have purchased storage capacity for Log Analysis or Agentic SOC.

2025-03-27

[Notice] Updates to Log Analysis and Agentic SOC

Anti-brute-force cracking

Updated

Security Center has added configuration options for SQL Server to mitigate the risk of brute-force attacks and database breaches.

Advanced, Enterprise, Ultimate

2025-03-14

Anti-brute-force cracking

Host and container security

Updated

Enable pay-as-you-go for host and container security and bind different protection editions to your servers.

All editions

2025-03-14

Terraform

Updated

Terraform documentation updated. Create an Agentic SOC module.

All editions

2025-03-06

Quickly enable Security Center by using Terraform

February 2025

Feature name

Change type

Description

Affected versions

Release date

Related documentation

Security control

Sunset

Sunsetting the security control feature in other configurations.

All versions

2025-02-14

Other configurations

January 2025

Feature name

Change type

Description

Affected editions

Release date

Related documentation

Multi-cloud asset onboarding

Enhancement

Configure an account name when onboarding multi-cloud assets to distinguish assets from different accounts of the same third-party cloud provider.

All editions

2025-01-12

Add third-party cloud assets

Agentic SOC

Enhancement

To avoid ingesting logs with low investigation value, Security Center checks whether you have purchased a paid edition (Anti-Virus Edition, Advanced Edition, Enterprise Edition, or Ultimate Edition) before ingesting ActionTrail logs based on the recommended policy.

If you have not purchased a paid edition, Security Center will not automatically ingest ActionTrail event logs, even if you have enabled the recommended log ingestion policy for Agentic SOC.

Requires the Agentic SOC value-added service.

2025-01-12

What is Agentic SOC

Serverless assets

Enhancement

The serverless security feature supports the protection of Container Service assets.

Available for users who have enabled pay-as-you-go for serverless assets.

2025-01-09

Serverless security

Client status change

Enhancement

The Security Center client supports additional statuses, including client offline, server powered off, and client not installed.

All editions

2025-01-07

Install client

Application Protection

Enhancement

Resource statistics include the number of PHP applications.

Requires the Application Protection value-added service.

2025-01-07

View RASP-protectable application list

Container Security

Enhancement

Container Security supports the protection of Lingjun Intelligent Computing assets.

Ultimate Edition

2025-01-02

Manage container assets

December 2024

Feature name

Change type

Description

Affected versions

Release date

Related documentation

Agentic SOC

Enhancement

When you enable pay-as-you-go for Agentic SOC, you can select a recommended log ingestion policy. This policy automatically ingests 14 types of logs from Alibaba Cloud products, including Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail.

Requires the Agentic SOC add-on.

2024-12-27

What is Agentic SOC

Ransomware protection

Enhancement

Ransomware protection for servers is now available in China (Ulanqab), China (Heyuan), and China (Guangzhou).

Requires the ransomware protection add-on.

2024-12-20

Ransomware protection service overview

Agentless detection

Enhancement

Agentless detection now supports incremental scans for custom images.

Available for users who have enabled pay-as-you-go for agentless detection.

2024-12-20

Agentless detection

Agentless detection now supports remediation for malicious samples and sensitive files.

Malicious file detection

Enhancement

The maximum file size for a single malicious file scan in OSS is now 500 MB.

Requires the malicious file detection add-on.

2024-12-18

Malicious file detection

Billing

Enhancement

Enable pay-as-you-go for Agentic SOC to access threat analysis and response capabilities, including product integration, incident response, security alerts, and response orchestration.

All editions

2024-12-13

Billing

Billing

Enhancement

Switch from full protection to on-demand protection. Select specific servers to protect for more flexible billing and protection.

All paid editions

2024-12-12

[Notice] Upgrade from full protection to on-demand protection

Cloud Security Posture Management

Enhancement

The cloud platform configuration check feature has been renamed to Cloud Security Posture Management.

Available to users with the cloud platform configuration check add-on.

2024-12-10

Cloud Security Posture Management

Application protection

New Feature

Application protection now supports PHP applications.

Requires the application protection add-on.

2024-12-06

What is application protection

Baseline check

Enhancement

Baseline checks now include operational metrics.

Advanced, Enterprise, and Ultimate

2024-12-03

Baseline risk check

November 2024

Feature name

Change type

Description

Availability

Release date

References

Image security scan

Enhancement

Export sensitive file information from image security scans, including image version and repository name.

Requires the image security scan add-on.

2024-11-21

View and handle image risks detected by scans

CI/CD integration settings

Enhancement

The documentation for Jenkins-Freestyle and Jenkins-Pipeline integration now provides more detailed steps and screenshots for integrating the plugin and configuring the image security scan.

Enterprise Edition

2024-11-19

Cloud platform configuration check

Enhancement

This feature now comprehensively scans and analyzes access paths between Alibaba Cloud resources, such as an ECS instance with a RAM role that grants access to an OSS bucket, and presents the results in a visual graph.

Requires the cloud platform configuration check add-on.

2024-11-19

Attack path analysis

Agentic SOC

Enhancement

The recommended log ingestion policy for Agentic SOC now ingests 14 log types from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail.

Requires the Agentic SOC add-on.

2024-11-15

What is Agentic SOC

Anti-ransomware

Enhancement

The anti-ransomware feature for databases now supports viewing backup tasks.

Requires the anti-ransomware add-on.

2024-11-15

Troubleshoot exceptions in database anti-ransomware policy status and backup tasks

The anti-ransomware feature now supports backing up data from Rocky Linux systems.

Requires the anti-ransomware add-on.

2024-11-13

Anti-ransomware overview

Billing

Enhancement

Use Terraform to purchase a subscription for the Agentic SOC add-on.

All users

2024-11-04

Quickly activate Security Center by using Terraform

October 2024

Feature

Change type

Description

Affected edition

Release date

Related documentation

Container microsegmentation

Enhancement

The container firewall feature is renamed to container microsegmentation.

Ultimate Edition

October 31, 2024

container microsegmentation

Image security scan

Enhancement

Now supports scanning GitLab image repositories.

Ultimate Edition

October 31, 2024

Configure and perform image security scans

Container assets

Enhancement

Now supports adding GitLab image repositories.

Ultimate Edition

October 31, 2024

Add an image repository

Anti-ransomware

Enhancement

Anti-ransomware policies for servers can now exclude non-local mount paths.

Requires the anti-ransomware add-on.

October 30, 2024

Create a protection policy and a client

Application Protection

Enhancement

Configure an application onboarding allowlist to control which applications RASP protects.

Requires the Application Protection add-on.

October 30, 2024

Onboard Application Protection

Agentic SOC

Enhancement

Cloud Workload Protection Platform (CWPP) and Agentic SOC alerts are now consolidated on a single page.

All editions

October 24, 2024

None

Brute-force protection

Enhancement

Advanced Edition users can now install the Alinet client plug-in to enhance brute-force protection with a cloud-based dynamic defense model.

Advanced Edition

October 24, 2024

[Notice] Enhancements to Brute-Force Protection in Security Center

Application Protection

Enhancement

The manual onboarding process for applications in container environments has been optimized, allowing you to customize the download and installation of the probe.

Requires the Application Protection add-on.

October 21, 2024

Onboard Application Protection

Core file monitoring

Enhancement

Now supports monitoring on Windows servers.

Enterprise Edition, Ultimate Edition

October 16, 2024

core file monitoring

Proactive container defense

Enhancement

Image restrictions for defense rules that target non-image programs have been optimized.

Ultimate Edition

October 16, 2024

Container image restrictions for rule effectiveness

Log Analysis

Enhancement

Log Analysis now supports shipping and storing alert logs from the core file monitoring feature.

Enterprise Edition, Ultimate Edition

October 15, 2024

Log Types and Field Descriptions

Anti-ransomware

Enhancement

The database anti-ransomware feature now supports backing up data from MySQL 8.0.

Requires the anti-ransomware add-on.

October 11, 2024

Anti-ransomware Service Overview

Agentless detection

Enhancement

Agentless detection is now supported in the China (Chengdu) region.

Available for users who have enabled pay-as-you-go for agentless detection.

October 9, 2024

agentless detection

September 2024

Feature

Type

Description

Editions

Date

Documentation

Serverless assets

Enhancement

Extends security checks to Serverless App Engine (SAE) products.

Users on the pay-as-you-go plan for serverless assets.

September 30, 2024

Serverless security

Asset exposure analysis

Enhancement

Asset exposure analysis now supports detection of additional asset types, including ApsaraDB for Tair (Redis-compatible), ApsaraDB RDS, and ApsaraDB for MongoDB.

Enterprise Edition and Ultimate Edition

September 27, 2024

Asset exposure analysis

Agentic SOC

Enhancement

The Attack Timeline tab on the security event details page is enhanced. Timeline cards now include alert and log evidence, and an event traceability graph. This feature also automatically traces suspicious attack paths. The graph displays rich node types, such as alerts, logs, vulnerabilities, baselines, assets, and entities, and lets you view details for each.

Requires the Agentic SOC add-on.

September 24, 2024

Security events

Deprecation

To improve the Agentic SOC log management experience, Security Center has discontinued the cold data feature, which was in public preview.

September 12, 2024

[Notice] End of public preview and discontinuation of the Agentic SOC cold data feature

Multi-cloud configuration management

Enhancement

The onboarding process for multi-cloud assets is now simpler. The SubscriptionId parameter is no longer required to onboard Azure assets.

All editions

September 5, 2024

Connect to third-party cloud assets

August 2024

Feature

Change type

Description

Affected versions

Release date

Related documentation

Agentic SOC

Enhancement

Added the aliyuncloudOpenAPI basic orchestration group.

Requires the Agentic SOC value-added service.

August 30, 2024

Response rules

Enhancement

Supports ingesting logs from third-party vendors, such as Chaitin WAF and Fortinet Firewall.

Requires the Agentic SOC value-added service.

August 20, 2024

Ingesting logs from security vendors

application protection

Enhancement

Supports runtime circuit breaker configuration.

Requires the application protection value-added service.

August 19, 2024

Onboarding application protection

cloud product configuration check

Enhancement

  • Lowered prices and introduced tiered billing for the pay-as-you-go method.

  • Lowered prices and introduced tiered billing for the subscription method.

Requires the cloud product configuration check value-added service.

August 19, 2024

application protection

Enhancement

Uses a large model to analyze attack alerts and webshell detection alerts, and provides detailed explanations and reasoning for each.

Requires the application protection value-added service.

August 16, 2024

Handling attack alerts

cloud product configuration check

Enhancement

  • Added new, free check items.

  • Added allowlist policy management.

All versions

August 2, 2024

serverless assets

General availability

  • The commercial version is now available, ending the public beta.

  • Supports security risk detection for assets from Elastic Container Instance (ECI), ACK Serverless clusters, and Serverless App Engine (SAE).

All versions

August 2, 2024

Serverless security

application protection

Enhancement

The webshell detection alert details page now includes a toggle to decompile Java files.

Requires the application protection value-added service.

August 1, 2024

Webshell protection

log analysis

Enhancement

Released log dictionary V2.0. Upgrade from V1.0 to V2.0.

Requires the log analysis value-added service.

August 1, 2024

July 2024

Feature

Type

Description

Versions

Date

Documentation

Malicious file scan SDK

Enhancement

Supports decrypting and scanning OSS data configured with server-side encryption.

Requires the malicious file detection add-on.

July 26, 2024

Malicious file detection

Agentless detection

Enhancement

Supports snapshot and custom image scanning.

Requires the pay-as-you-go service for agentless detection.

July 8, 2024

Agentless detection

Agentic SOC

Enhancement

Supports copying playbooks.

Requires the Agentic SOC add-on.

July 3, 2024

Response rule

Core file monitoring

Enhancement

Published a best practices guide for configuring core file monitoring rules.

Enterprise Edition, Ultimate Edition

July 1, 2024

Best practices for core file monitoring configuration

June 2024

Feature

Change type

Description

Affected editions

Release date

Related documentation

Malicious file detection SDK

Enhancement

The Security Center console now displays detection results for malicious files identified as risky by API detection.

Requires the malicious file detection value-added service.

June 28, 2024

Malicious file detection

Deliver malicious file detection logs to a dedicated Logstore in Security Center.

Malicious file detection logs

Configure DingTalk chatbot notifications to receive real-time alerts about detected malicious files.

Configure DingTalk chatbot notifications

Vulnerability management

Enhancement

Vulnerability management now supports scanning for vulnerabilities in SUSE and Kylin operating systems.

All editions

June 20, 2024

Vulnerability management overview

Application Protection

Enhancement

  • Identify and list application processes eligible for Application Protection.

  • On the Vulnerabilities tab of the Application Vulnerability page, you can now onboard assets that have application vulnerabilities to Application Protection.

  • On the Application Protection page, the Application Analysis tab now displays statistics and trend charts related to vulnerability defense.

Requires the Application Protection value-added service.

June 19, 2024

What is Application Protection?

Agentic SOC

Enhancement

Agentic SOC now supports ingesting DCDN Edge Routine logs, DCDN user access logs, and DCDN WAF logs for threat detection, incident response, orchestration, and log storage.

Requires the Agentic SOC value-added service.

June 19, 2024

What is Agentic SOC?

Baseline check

Enhancement

Baseline check now supports additional operating systems, including Debian 10, 11, and 12, and TencentOS Server 3.1.

Advanced, Enterprise, and Ultimate

June 19, 2024

Baseline risk checks

Enhancement

Upload weak password dictionaries up to 40 KB.

Advanced, Enterprise, and Ultimate

June 7, 2024

Baseline risk checks

Agent deployment

Enhancement

The agent now supports installation on Kylin V7 and RHEL 9.

All editions

June 6, 2024

Operating systems supported by the agent

Log analysis

Enhancement

Log analysis now supports the delivery and storage of agent event logs.

Requires the log analysis value-added service.

June 6, 2024

Log fields

May 2024

Feature

Change type

Description

Affected editions

Release date

Related documentation

Image security scan

Enhancement

The image security scan feature is now available in the China (Ulanqab) region.

Requires the image security scan add-on.

2024-05-31

Image security scan overview

Container assets

Enhancement

Export risk detection results for individual image assets.

Ultimate Edition

2024-05-31

Manage container assets

Product purchase

Enhancement

When you purchase a subscription Security Center instance, you can select the number of servers and the vCPU count. You must then manually manage the number of licenses.

Anti-Virus Edition, Advanced Edition, Enterprise Edition, Ultimate Edition

2024-05-30

Manage licenses for host and container security

Security alert handling

Enhancement

The alert name Anomalous Process Behavior - Suspicious Command has been changed to Command and Control.

Anti-Virus Edition, Advanced Edition, Enterprise Edition, Ultimate Edition

2024-05-22

Overview of CWPP security alerts

Application protection

Enhancement

The wording on the attack alert details page has been revised for clarity.

Requires the application protection add-on.

2024-05-15

Handle attack alerts

Malicious file detection

Enhancement

The maximum file size for malicious file detection has been increased from 20 MB to 100 MB.

Requires the malicious file detection add-on.

2024-05-14

Malicious file detection

Cloud platform configuration check

Enhancement

  • The number of free check items available to users of the Free Edition has increased from 25 to over 60.

  • Free checks do not consume the quota for users of paid editions.

To use this feature, you must either purchase a quota for cloud platform configuration checks or enable pay-as-you-go.

2024-05-11

Cloud Security Posture Management overview

Agentic SOC

Enhancement

The time range picker and filter on the Security Incidents page have been optimized.

Requires the Agentic SOC add-on.

2024-05-09

Security events

April 2024

Feature

Change type

Description

Affected editions

Release date

Related documentation

Agentic SOC

Enhancement

  • The service uses a tiered pricing model based on the volume of logs ingested and the amount of hot storage required.

  • Analysis and response capabilities, such as security alerts, incident response, and orchestrated response, are separate from log storage. This allows you to flexibly choose whether to purchase log storage capacity.

  • You can designate a global administrator to centrally manage security incidents across multiple Alibaba Cloud accounts.

Users who have purchased the Agentic SOC value-added service.

April 26, 2024

[Notice] Agentic SOC Billing Changes

Application protection

New feature

The new memory trojan defense feature detects threats hidden in memory.

Users who have purchased the application protection value-added service.

April 17, 2024

Memory trojan defense

Cloud platform configuration check

Enhancement

Security Center now provides a one-click fix for over 50 check items.

Users who have purchased a quota for cloud platform configuration checks or enabled pay-as-you-go for this feature.

April 17, 2024

Configure and run a check policy

Anti-ransomware (decoy capture)

Enhancement

This feature now supports Linux servers.

Advanced, Enterprise, or Ultimate

April 17, 2024

Host protection settings

Baseline check

Enhancement

The CIS compliance baseline type has been renamed to International General Security Best Practices.

Advanced, Enterprise, or Ultimate

April 11, 2024

Baseline risk check

Malicious file detection

Enhancement

Malicious file detection can now decompress and scan compressed files.

Users who have purchased the malicious file detection value-added service.

April 11, 2024

Malicious file detection

Agentic SOC log management

New feature

  • The Log Analysis page has been renamed to Log Management.

  • The original Log Management feature has been renamed to Hot Data.

  • The log management feature now includes a new Cold Storage Settings feature, which provides a lower-cost storage option.

Users who have purchased the Agentic SOC value-added service.

April 2, 2024

Log management

Cloud platform configuration check

Enhancement

The Security Center console now restricts cloud platform configuration checks for Resource Access Management (RAM) by account location. Alibaba Cloud accounts registered on the China site can only scan RAM check items in China regions. Accounts registered on the international site can only scan these items in regions outside of Chinese mainland. Historical scan results are retained in their respective regions.

Users who have purchased a quota for cloud platform configuration checks or enabled pay-as-you-go for this feature.

April 1, 2024

[Cloud Platform Configuration Check] RAM-related checks are restricted to the account's registration region

March 2024

Feature

Type

Description

Versions

Date

Documentation

Agentic SOC

Updated

The threat analysis feature has been renamed to Agentic SOC.

Requires the Agentic SOC add-on.

2024-03-29

What is Agentic SOC (formerly threat analysis)

Container file protection

Updated

You can configure a process whitelist and a file and directory whitelist when you create rules for container file protection.

Ultimate Edition

2024-03-19

Container file protection

Malicious file detection

Updated

Malicious file detection supports additional malware types, including adware, cracking tools, and private server tools.

Requires the malicious file detection add-on.

2024-03-01

Malicious file detection

February 2024

Feature name

Change type

Description

Affected edition

Release date

Related documentation

core file monitoring

Enhancement

Receive core file monitoring alert notifications via a DingTalk robot.

Enterprise Edition, Flagship Edition

February 23, 2024

Configure notification settings

baseline check

Enhancement

The custom weak password feature now lets you append new weak passwords to an existing dictionary.

Advanced Edition, Enterprise Edition, Flagship Edition

February 22, 2024

baseline risk checks

application protection

Enhancement

  • Use protection policy groups for fine-grained control over detection types and modes (Standard, Loose, and Strict).

  • On the Application Protection > Attack Alerts tab, an option to add items to the allowlist has been added.

Requires the application protection value-added service.

February 22, 2024

Connect to application protection

cloud platform configuration check

Enhancement

Pay-as-you-go billing is now supported.

All editions

February 19, 2024

Overview of CSPM

agentless detection

Enhancement

The agentless detection feature is now generally available and has become a paid service. If you are an existing user, you can continue using the feature for free until the public preview concludes on March 5, 2024. To use the feature beyond this date, you must switch to the pay-as-you-go billing model.

All editions

February 2, 2024

End of public preview for agentless detection

January 2024

Feature name

Change type

Description

Affected editions

Release date

Related documentation

Security report

Enhancement

Optimized the security report page in the console.

Advanced Edition, Enterprise Edition, Ultimate Edition

2024-01-31

Security report

Overview

Enhancement

Optimized the content in the Security Information module.

All editions

2024-01-29

Overview (old version)

Risk governance

Enhancement

Renamed the risk management module to risk governance.

All editions

2024-01-26

None

Cloud platform configuration check

Enhancement

Users without a quota for cloud platform configuration check can now use 25 check items for free.

All editions

2024-01-19

Cloud security posture management overview

Vulnerability management

Enhancement

The Show Only Exploitable Vulnerabilities feature is now available in the Global (excluding China mainland) region.

All editions

2024-01-05

View and handle vulnerabilities

Release history

For Security Center feature releases before 2024, see Feature Release Notes (before 2024).